New XCSSET Malware Variant Targets macOS App Developers
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects. This variant introduces sophisticated clipboard hijacking and enhanced data exfiltration capabilities.
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects. This variant introduces sophisticated clipboard hijacking and enhanced data exfiltration capabilities.
Microsoft Threat Intelligence has detected a new XCSSET variant that includes further updates and new modules beyond previous analyses. The malware infects Xcode projects, commonly used by software developers, and operates during the build process of an Xcode project.
This variant of XCSSET brings notable changes related to browser targeting, clipboard hijacking, and persistence mechanisms. It employs advanced encryption and obfuscation techniques, utilizes run-only compiled AppleScripts for stealthy execution, and expands its data exfiltration capabilities to include Firefox browser data.
The malware also introduces another persistence mechanism through LaunchDaemon entries, complicating detection and removal.
The latest XCSSET variant follows a four-stage infection chain, with the fourth stage introducing several new malicious modules. The vexyeqj info-stealer module downloads and executes a run-only compiled AppleScript called "bnk," which performs sophisticated clipboard monitoring and cryptocurrency wallet hijacking.
This module uses AES encryption with a hardcoded key to decrypt configuration data from command and control servers. The clipboard hijacking functionality is particularly advanced, verifying the clipboard content against cryptocurrency wallet address patterns and replacing legitimate addresses with attacker-controlled alternatives.
A new iewmilh_cdyd module targets Firefox browser data, downloading a modified version of the HackBrowserData project. This binary extracts passwords, browsing history, credit card information, and cookies from Firefox installations. The data is compressed into ZIP files and sent to command and control servers.
The neq_cdyd_ilvcmwx file-stealer module retrieves additional scripts from command and control servers and operates as a compiled AppleScript, similar to previous wallet data stealers but with enhanced file exfiltration capabilities.
The xmyyeqjx module establishes LaunchDaemon-based persistence by creating a ~/.root file and associated plist entries, masquerading as legitimate system processes. This module also disables macOS automatic updates and Rapid Security Response mechanisms, weakening system defenses.
Security experts recommend maintaining updated operating systems and applications, inspecting Xcode projects from external sources, and handling clipboard data with caution, especially cryptocurrency addresses.
Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects.
Microsoft suggests using browsers with SmartScreen protection, deploying Microsoft Defender for Endpoint on Mac, and enabling cloud-delivered protection with automatic sample submission. Network protection should be activated to block connections to malicious domains associated with this campaign.
Indicator Type Description
cdntor[.]ru Domain C2 server
checkcdn[.]ru Domain C2 server
cdcache[.]ru Domain C2 server
applecdn[.]ru Domain C2 server
flowcdn[.]ru Domain C2 server
elasticdns[.]ru Domain C2 server
rublenet[.]ru Domain C2 server
figmastars[.]ru Domain C2 server
bulksec[.]ru Domain C2 server
dobetrix[.]ru Domain C2 server
figmacat[.]ru Domain C2 server
digichat[.]ru Domain C2 server
diggimax[.]ru Domain C2 server
cdnroute[.]ru Domain C2 server
Based on reporting by GBHackers.
